Reference / XBT Card Signer

A clearer path
from card to chain.

Reference for the 0.4 personal testing candidate. Android performs card signing; an XBT-aware Knots node prepares and broadcasts the transaction.

Public release is pending.

No public APK, Google Play listing or GitHub repository is available. The pinned Tangem SDK requires distribution rights clearance. This guide is documentation, not a browser signer.

What you need

RPC stays local to your node. Your phone does not need node credentials, and a VM does not need NFC passthrough.

1. Match your card

Enter your payout address, choose Read Tangem card and scan the card. If a root key does not match, select the secp256k1 wallet and enter the actual Bitcoin derivation path used by your Tangem wallet.

The path m/84'/0'/0'/0/0 is a candidate, not a universal value. Continue only after a match. In a public-key report, derived_public_key is the descriptor leaf key; wallet_public_key selects the card’s root wallet.

2. Prepare a watch-only wallet

Substitute your actual node data directory and matched public key. The example directory below is /bitcoin.

bitcoin-cli -datadir=/bitcoin getblockchaininfo
bitcoin-cli -datadir=/bitcoin -named createwallet \
  wallet_name="xbt-card-watch" disable_private_keys=true \
  blank=true descriptors=true load_on_startup=true
bitcoin-cli -datadir=/bitcoin \
  getdescriptorinfo "wpkh(YOUR_DERIVED_PUBLIC_KEY)"

Import the returned descriptor, including its checksum:

bitcoin-cli -datadir=/bitcoin -rpcwallet=xbt-card-watch \
  importdescriptors \
  '[{"desc":"YOUR_CHECKSUMMED_DESCRIPTOR","timestamp":"now","active":false,"internal":false,"label":"Card XBT"}]'

Recovering older funds requires a rescan. Importing with timestamp: now does not discover older transactions. Check the node’s pruning status and rescan from a retained height at or before your first relevant transaction. Deleted blocks require an archival node.

bitcoin-cli -datadir=/bitcoin -rpcwallet=xbt-card-watch \
  -rpcclienttimeout=0 rescanblockchain YOUR_RETAINED_START_HEIGHT
bitcoin-cli -datadir=/bitcoin -rpcwallet=xbt-card-watch \
  listunspent 1 9999999 '["YOUR_CARD_ADDRESS"]'

3. Prepare an unsigned PSBT

Select confirmed, mature, safe UTXOs and verify the recipient independently. The example sends 0.1 XBT, uses one explicitly selected input and returns change to your card. Replace every placeholder before running it.

bitcoin-cli -datadir=/bitcoin -rpcwallet=xbt-card-watch \
  walletcreatefundedpsbt \
  '[{"txid":"YOUR_SELECTED_TXID","vout":0}]' \
  '[{"YOUR_RECIPIENT_ADDRESS":0.1}]' 0 \
  '{"add_inputs":false,"includeWatching":true,"changeAddress":"YOUR_CARD_ADDRESS","changePosition":1,"fee_rate":1,"replaceable":false,"lockUnspents":false}' false

In the tested Knots RPC, fee_rate is sats/vB. The app’s fee limit is the total fee in sats. This single-address watch wallet needs an explicit change address. Review the node’s PSBT and fee before transferring it.

4. Review and sign on Android

  1. Transfer the unsigned PSBT to the phone. The candidate supports pasted base64, binary PSBT files and UTF-8 base64 text files up to 1 MiB.
  2. Match your card address and set the maximum total fee.
  3. Review every full destination address, amount, return-to-card output and total fee.
  4. Confirm the review explicitly, then choose Sign with Tangem card and scan the same card.
  5. After signatures verify, copy or save the signed PSBT and return it to your node.

A signed PSBT authorizes the transaction; someone holding it can finalize and broadcast it. The app cannot broadcast. Changing the address, path, PSBT or fee clears prior export authorization. Restarting requires rematching your card.

5. Validate before broadcasting

read -r -p "Paste signed PSBT: " XBT_SIGNED_PSBT
bitcoin-cli -datadir=/bitcoin finalizepsbt "$XBT_SIGNED_PSBT"

Expect complete: true and transaction hex. An incomplete result can indicate that the original unsigned PSBT was copied instead of the signed export.

read -r -p "Paste finalized transaction hex: " XBT_TX_HEX
bitcoin-cli -datadir=/bitcoin \
  testmempoolaccept "[\"$XBT_TX_HEX\"]"
bitcoin-cli -datadir=/bitcoin decoderawtransaction "$XBT_TX_HEX"

Verify allowed: true and recheck the recipient, amount, change and fee. These checks do not broadcast. When you intend to send the exact reviewed transaction:

bitcoin-cli -datadir=/bitcoin sendrawtransaction "$XBT_TX_HEX"
bitcoin-cli -datadir=/bitcoin -rpcwallet=xbt-card-watch \
  gettransaction "RETURNED_TXID"

Zero confirmations means pending. Check for confirmations later; do not create a second payment simply because the first is waiting.

Integration boundaries

The integration is an unsigned/signed PSBT exchange. Other wallets must understand the XBT chain and ALL|UNIFIED signing (0x21). Standard Bitcoin PSBT support alone is insufficient.

Testing & release status

Candidate: 0.4.0-rc1. Updated October 8, 2026.

The recorded build evidence reports 7 Python test methods including 166 Knots signing vectors, 13 Android unit tests, and passing release lint. The debug APK and unsigned AAB were built. The 0.4 interface, file providers, accessibility and release variant still require physical-device acceptance. No independent security audit is claimed.

The pinned Tangem SDK has proprietary distribution terms. Public SDK-dependent app publication requires rights clearance. The current app binaries are for personal testing; there are no public downloads here.

Privacy in the candidate

The app has no Internet permission, account, analytics or app-side server. It locally reads public-key/card metadata, reviews transaction data and verifies card signatures. Private keys remain on the card.

Explicit copy/export can place information on the OS clipboard or a selected file provider, which may sync under its own policy. Public addresses and reports can reveal wallet relationships. Do not share access codes, seeds or recovery material in support requests.

This is a technical privacy summary for the testing candidate. A publisher policy and support contact must be finalized before public app release.

Return to ACME Crypto